Methodology
How a review runs
A repeatable path for application security event and anomaly analytics engagements, designed so owners always know what happens next.
Our flagship Security Event Analytics Review follows five stages. Investigations and workshops borrow the same discipline at a shorter length.
-
Scope and constraints
We confirm applications in scope, event stores, privacy limits, and the decisions you need the review to support. You receive a written fee basis before samples move.
-
Sample window
Together we choose a contiguous window — often seven to fourteen days — plus any known anomaly periods. Exports or limited read access are arranged so production change freezes are respected.
-
Event inventory
We catalogue security-relevant events: authentication outcomes, authorization denials, privilege changes, and other application decisions that should leave a trail.
-
Anomaly and coverage analysis
Using the inventory, we test whether abuse scenarios and silence conditions can be answered. Findings are ranked by decision value, not chart density.
-
Delivery and clarification
You receive a written report, a walkthrough meeting, and two clarification calls within thirty days. Remediation owners are named where your org chart allows.
What you prepare
- A technical contact per application
- Architecture sketch of event producers and stores
- Notes on known quirks: duplicates, clock skew, dual logging
- Any PIPA or contractual limits on field sharing
Ready to put a review on the calendar?
Browse engagements or send a short brief describing the applications you want examined.